Malicious PDF — malware analysis report

Static analysis result for SHA-256 04fbbfeb91c2bf73…

MALICIOUS

PDF

17.7 KB Created: 2019-05-04 11:12:59 +01:00 Authoring application: mPDF 5.7
MD5: ccdab3847a9668414c154d997b0e5efa SHA-1: e4169344835cd0fb1ad392130894671e269f1016 SHA-256: 04fbbfeb91c2bf7360d03bb0ee184bf757dcec4903076d895ab7f30e8f5b4f95
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, many of which are structured as numeric slugs, indicating a potential SEO link farm. While the extracted URLs themselves are labeled as benign, the sheer volume and structure suggest a malicious intent to manipulate search engine rankings or redirect users to potentially harmful content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/3730730737738733/Sherman-s-Lagoon-1991-to-2001-Greatest-Hits-and-Near-Misses-by-Jim-Toomey.pdf
    • http://cefasfese.4pu.com/3730730737738737/Catch-of-the-Day-Sherman-s-Lagoon-Collection-8-by-Jim-Toomey.pdf
    • http://cefasfese.4pu.com/3730730737738732/Another-Day-in-Paradise-The-Fourth-Sherman-s-Lagoon-Collection-by-Jim-Toomey.pdf
    • http://cefasfese.4pu.com/3730730737739730/A-Day-at-the-Beach-The-Ninth-Sherman-s-Lagoon-Collection-by-Jim-Toomey.pdf
    • http://cefasfese.4pu.com/8730739735739738/The-Supremes-Greatest-Hits-The-34-Supreme-Court-Cases-That-Most-Directly-Affect-Your-Life-by-Michael-G-Trachtman.pdf
    • http://cefasfese.4pu.com/1730738738734735733/Albums-Produced-by-Leon-Ware-I-Want-You-the-Master-Anthology-Marvin-Gaye-the-Very-Best-of-Marvin-Gaye-Marvin-Gaye-s-Greatest-Hits-by-Books-LLC.pdf
    • http://cefasfese.4pu.com/2736735734732730/Dave-Barry-s-Greatest-Hits-by-Dave-Barry.pdf
    • http://cefasfese.4pu.com/3739739730739734/The-Librarian-from-the-Black-Lagoon-Black-Lagoon-5-by-Mike-Thaler.pdf
    • http://cefasfese.4pu.com/1730735734737734/The-Teacher-from-the-Black-Lagoon-Black-Lagoon-1-by-Mike-Thaler.pdf
    • http://cefasfese.4pu.com/4730731736737737/The-Misses-Mallett-The-Bridge-Dividing-by-E-H-Young.pdf
    • http://cefasfese.4pu.com/4730736732734733/Memoirs-of-General-William-T-Sherman-by-William-T-Sherman.pdf
    • http://cefasfese.4pu.com/2730734734732732/To-Love-a-Reckless-Lord-Conundrums-of-the-Misses-Culpepper-Collection-Books-1-3-by-Collette-Cameron.pdf
    • http://cefasfese.4pu.com/9733735732736/Before-the-Sun-Hits-by-Arthur-Swan.pdf
    • http://cefasfese.4pu.com/8731733731735/Biggles-Hits-the-Trail-by-W-E-Johns.pdf
    • http://cefasfese.4pu.com/3730736736738730/Big-Papi-My-Story-of-Big-Dreams-and-Big-Hits-by-David-Ortiz.pdf
    • http://cefasfese.4pu.com/1734733736737739/The-Billboard-Book-of-Top-40-Country-Hits-by-Joel-Whitburn.pdf
    • http://cefasfese.4pu.com/5734739735738737/The-Caligula-Club-Hits-the-Brick-Wall-by-Richard-Forsythe.pdf
    • http://cefasfese.4pu.com/3737732730738739/The-Lost-Lagoon-1-by-J-M-Keep.pdf
    • http://cefasfese.4pu.com/1732736732736734/Lagoon-by-Nnedi-Okorafor.pdf
    • http://cefasfese.4pu.com/3739735737730732/Black-Lagoon-Vol-5-by-Rei-Hiroe.pdf